Impact
NVIDIA Dynamo for Linux contains a server‑side request forgery vulnerability (CWE‑918) that allows an attacker to supply a crafted URL and cause Dynamo to make outbound HTTP requests to arbitrary destinations. If an attacker successfully causes such a request, information that should remain confidential—such as internal service responses or user data—can be accessed and exfiltrated, thereby compromising the system's confidentiality.
Affected Systems
The affected product is NVIDIA Dynamo for Linux. No specific vulnerable versions are listed in the available data, so all releases prior to the fix should be considered at risk.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity. The EPSS score is not available, so the current exploitation probability is unclear. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a network endpoint that communicates with Dynamo; an attacker would need to trigger the SSRF by sending a specially crafted request to the service.
OpenCVE Enrichment